What’s the Scam?
A coordinated campaign is flooding in with generic, overly enthusiastic responses to automated emails from a security newsletter (Crypto-Gram). The emails are designed to elicit a response and potentially initiate a social engineering scam, likely involving a ‘pig butchering’ scheme. The addresses used are clearly fake and not associated with actual Crypto-Gram subscribers.
A wave of automated responses has been targeting the Crypto-Gram newsletter, a security news platform. The emails, sent to subscribers, contain overwhelmingly positive and generic messages praising the newsletter's impact. These responses are not from actual subscribers; the addresses used are entirely fabricated and do not correspond to anyone who has signed up for the newsletter. The campaign began last weekend and has rapidly escalated, with a large volume of emails arriving simultaneously.
The emails themselves are remarkably consistent, expressing gratitude and highlighting the value of the newsletter. However, the addresses used are clearly fake, consisting of randomly generated strings of characters, all utilizing Gmail accounts. This suggests a deliberate attempt to bypass automated spam filters and to create a sense of legitimacy. The campaign’s goal appears to be to encourage recipients to respond to the emails, potentially starting a conversation and leading to a ‘pig butchering’ scheme – a type of social engineering where scammers build trust before attempting to defraud victims.